Cisco Asa 5580 Firmware vulnerabilities
24 known vulnerabilities affecting cisco/asa_5580_firmware.
Total CVEs
24
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH15MEDIUM7
Vulnerabilities
Page 2 of 2
CVE-2020-3188MEDIUMCVSS 5.3v9.8\(3\)v101.6\(1.96\)2020-05-06
CVE-2020-3188 [MEDIUM] CWE-399 CVE-2020-3188: A vulnerability in how Cisco Firepower Threat Defense (FTD) Software handles session timeouts for ma
A vulnerability in how Cisco Firepower Threat Defense (FTD) Software handles session timeouts for management connections could allow an unauthenticated, remote attacker to cause a buildup of remote management connections to an affected device, which could result in a denial of service (DoS) condition. The vulnerability exists because the default sessi
nvd
CVE-2020-3186MEDIUMCVSS 5.3v9.12\(1.6\)v201.5\(23.16\)2020-05-06
CVE-2020-3186 [MEDIUM] CWE-284 CVE-2020-3186: A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD)
A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured management interface access list on an affected system. The vulnerability is due to the configuration of different management access lists, with ports allowed in one access l
nvd
CVE-2011-2054HIGHCVSS 7.5v8.4\(1\)2020-02-19
CVE-2011-2054 [MEDIUM] CWE-287 CVE-2011-2054: A vulnerability in the Cisco ASA that could allow a remote attacker to successfully authenticate usi
A vulnerability in the Cisco ASA that could allow a remote attacker to successfully authenticate using the Cisco AnyConnect VPN client if the Secondary Authentication type is LDAP and the password is left blank, providing the primary credentials are correct. The vulnerabilities is due to improper input validation of certain parameters passed to the af
nvd
CVE-2019-15256HIGHCVSS 8.6v9.9\(2.4\)v201.4\(1.21\)2019-10-02
CVE-2019-15256 [HIGH] CWE-399 CVE-2019-15256: A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Ap
A vulnerability in the Internet Key Exchange version 1 (IKEv1) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due to improper ma
nvd
← Previous2 / 2